JSCEAL Malware Spread Through Fake Cryptocurrency Exchange Ads on Facebook

· Original article ↗

Summary

AhnLab reports that Facebook ads impersonating a cryptocurrency exchange distributed JSCEAL to Windows and macOS users in Korea. About 1,500 PC infections were confirmed over August and September 2026.

Key points

  • The ads offered cryptocurrency rewards for installing an exchange program and redirected users to a fake exchange site.
  • The site generated different installers by operating system: a BAT file for Windows and a PKG file for macOS.
  • On Windows, the BAT file used PowerShell to download and run more code, create scheduled-task persistence, add a Microsoft Defender exclusion, and launch JSCEAL using Node.js.
  • On macOS, the PKG installer downloaded scripts, prompted users for their account password, and sent system details and clipboard data to an external server.
  • The macOS infection also registered a LaunchAgent to enable follow-up commands and execute additional JSCEAL payloads.
  • AhnLab advises checking for suspicious scripts, persistence, Defender exclusions, credential prompts, and related execution traces; users should download exchange software only from official sites.

Article Details

Attack Vectors
  • Facebook ads promising cryptocurrency rewards led users to a site impersonating a cryptocurrency exchange.
  • The site checked the visitor's operating system and generated a BAT installer for Windows or a PKG installer for macOS.
  • On Windows, the BAT file used PowerShell to download and execute additional code. The malware added a Microsoft Defender exclusion, registered scheduled tasks, and used an embedded Node.js runtime to execute JSCEAL.
  • On macOS, a script in the PKG installation process downloaded and ran another shell script. It prompted for the user's password, collected system and clipboard information, and registered a LaunchAgent for subsequent execution.
Defensive Notes
  • On Windows, review PowerShell execution and downloads, Microsoft Defender exclusions, scheduled tasks, the Users\Public\Desktop\Binance.LNK shortcut, and Node.js execution of JavaScript or V8 bytecode.
  • On macOS, review installer-initiated shell scripts, unexpected password prompts and stored passwords, external transmission of system or clipboard data, LaunchAgents, and subsequent JavaScript execution.
  • Download cryptocurrency exchange software from its official website rather than running BAT or PKG files from unknown sources. Stop and verify the source if installation unexpectedly requests a password.

MITRE ATT&CK

Malware

Vendors

Products

Countries

Related Articles